From a73891a3b84fbc6a42bf3bedf9b1cad6e66c6569 Mon Sep 17 00:00:00 2001 From: bunkerity Date: Thu, 10 Dec 2020 21:42:24 +0100 Subject: [PATCH] fix CVE-2020-8231 --- Dockerfile | 4 ++-- Dockerfile-amd64 | 4 ++-- Dockerfile-arm32v7 | 4 ++-- Dockerfile-arm64v8 | 4 ++-- Dockerfile-i386 | 4 ++-- 5 files changed, 10 insertions(+), 10 deletions(-) diff --git a/Dockerfile b/Dockerfile index f452de1..2b27840 100644 --- a/Dockerfile +++ b/Dockerfile @@ -31,8 +31,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-amd64 b/Dockerfile-amd64 index 6807788..669a180 100644 --- a/Dockerfile-amd64 +++ b/Dockerfile-amd64 @@ -31,8 +31,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-arm32v7 b/Dockerfile-arm32v7 index fae988a..85d601c 100644 --- a/Dockerfile-arm32v7 +++ b/Dockerfile-arm32v7 @@ -38,8 +38,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-arm64v8 b/Dockerfile-arm64v8 index 2c9a757..f976bc5 100644 --- a/Dockerfile-arm64v8 +++ b/Dockerfile-arm64v8 @@ -38,8 +38,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache diff --git a/Dockerfile-i386 b/Dockerfile-i386 index b3f24fd..23e9294 100644 --- a/Dockerfile-i386 +++ b/Dockerfile-i386 @@ -31,8 +31,8 @@ RUN apk --no-cache add certbot libstdc++ libmaxminddb geoip pcre yajl fail2ban c chown root:nginx /acme-challenge && \ chmod 750 /acme-challenge -# Fix CVE-2020-28928 -RUN apk --no-cache add "musl-utils>1.1.24-r2" +# Fix CVE-2020-28928 & CVE-2020-8231 +RUN apk --no-cache add "musl-utils>1.1.24-r2" "libcurl>7.67.0-r1" VOLUME /www /http-confs /server-confs /modsec-confs /modsec-crs-confs /cache